Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-88940

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Sep 10, 2026
Vendor unknown

Description

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

References